Hermes AI: Thai Finance Ministry Cyberattack Automated
Summary
A threat actor used an open-source AI agent called Hermes to automate part of an alleged cyberattack against Thailand's Ministry of Finance. This activity was uncovered by threat intelligence company Hunt.io and security researcher Bob Diachenko. They found several exposed web directories containing hundreds of files linked to the operation. These files included exploit code, web shells, and logs generated by the Hermes AI agent. Hunt.io states that evidence points to multiple systems within the ministry's network being compromised. However, the Ministry of Finance has not confirmed any breach. The recovered files referenced ministry systems by name and included scripts targeting internal services like Hadoop infrastructure and mail servers. Researchers also found a PHP web shell deployed on a ministry web server. This incident highlights the growing use of AI in automated cyberattacks.
This is an AI-generated audio summary. Always check the original source for complete reporting.